Attack Tool(s): Rubeus, Impacket, Hashcat, NetExec
- Rubeus: https://github.com/GhostPack/Rubeus
- Impacket: https://github.com/SecureAuthCorp/impacket
- Hashcat: https://hashcat.net/hashcat
- NetExec: https://github.com/Pennyw0rth/NetExec
Detection Link(s):
- Security Information and Event Management (SIEM) Log Analysis
- User and Entity Behavior Analytics (UEBA)
- Active Defense and Cyber Deception
- Endpoint Security Protection Analysis
Helpful Blogs (BHIS):
- “One Active Directory Account Can Be Your Best Early Warning” – https://www.blackhillsinfosec.com/one-active-directory-account-can-be-your-best-early-warning
- “Running Hashcat on Ubuntu” – https://www.blackhillsinfosec.com/running-hashcat-on-ubuntu-18-04-server-with-1080ti – Hashcat guide.
